VDB
Sign up
HIGH7.5

GHSA-qmvq-f3fj-m3wg

OpenPGP 1.2.0 and earlier decrypts arbitrary messages

Quick fix

GHSA-qmvq-f3fj-m3wg — openpgp: upgrade to the fixed version with the command below.

npm install openpgp@1.3.0

Details

s2k.js in OpenPGP.js will decrypt arbitrary messages regardless of passphrase for crafted PGP keys which allows remote attackers to bypass authentication if message decryption is used as an authentication mechanism via a crafted symmetrically encrypted PGP message.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/openpgp
Introduced in: 0Fixed in: 1.3.0
Fixnpm install openpgp@1.3.0

References